Security

Last updated: 8/10/2026

Reporting a vulnerability

If you believe you've found a security issue in this website or in a system we operate, please email security@it-empowered.com with enough detail for us to reproduce it. We aim to acknowledge reports within two business days.

Please give us a reasonable window to investigate and remediate before disclosing publicly, and avoid actions that could degrade service or access data that isn't yours — testing that stops at proving the issue exists is always welcome.

Our machine-readable contact details are published at /.well-known/security.txt.

How we protect information

  • Staff accounts are invitation-only, support authenticator-app two-factor authentication, and screen new passwords against known breach lists.
  • Inactive staff sessions are signed out automatically, and staff can sign out of every device at once.
  • Access to client records is restricted by role, enforced in the database rather than only in the interface.
  • Security-relevant actions are written to an append-only activity log that cannot be edited or deleted through the application.
  • Documents are stored privately and shared through short-lived links rather than permanent public URLs.
  • Data is encrypted in transit, and public forms are rate limited to resist abuse.

Scope

This page covers it-empowered.com and the staff portal hosted on it. Client systems we build or maintain are covered by the security terms in that client's agreement.

Note

This page describes our own practices. It is not a certification, audit result, or claim of compliance with any specific framework.